CVE-2017-7788: Critical severity firefox vulnerability
When an "iframe" has a "sandbox" attribute and its content is specified using "srcdoc", that content does not inherit the containing page's Content Security Policy (CSP) as it should unless the sandbox attribute included "allow-same-origin". This vulnerability affects Firefox < 55.
Other sources
When an iframe has a sandbox attribute and its content is specified using srcdoc, that content does not inherit the containing page's Content Security Policy (CSP) as it should unless the sandbox attribute included allow-same-origin.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2017-7798
- CVE-2017-7800
- CVE-2017-7801
- CVE-2017-7809
- CVE-2017-7784
- CVE-2017-7802
- CVE-2017-7785
- CVE-2017-7786
- CVE-2017-7806
- CVE-2017-7753
- CVE-2017-7787
- CVE-2017-7807
- CVE-2017-7792
- CVE-2017-7804
- CVE-2017-7791
- CVE-2017-7808
- CVE-2017-7782
- CVE-2017-7781
- CVE-2017-7794
- CVE-2017-7803
- CVE-2017-7799
- CVE-2017-7783
- CVE-2017-7788
- CVE-2017-7789
- CVE-2017-7790
- CVE-2017-7796
- CVE-2017-7797
- CVE-2017-7780
- CVE-2017-7779
Frequently Asked Questions
What is the severity of CVE-2017-7788?
CVE-2017-7788 is considered a moderate severity vulnerability.
How do I fix CVE-2017-7788?
To fix CVE-2017-7788, update Firefox to version 55 or later.
What versions of Firefox are affected by CVE-2017-7788?
CVE-2017-7788 affects Firefox versions before 55.
What type of vulnerability is CVE-2017-7788?
CVE-2017-7788 is a vulnerability related to the handling of iframe sandbox attributes and Content Security Policy.
What can happen if CVE-2017-7788 is exploited?
If exploited, CVE-2017-7788 can allow an iframe to bypass the intended Content Security Policy, possibly leading to security breaches.